Hannaford Data Theft Was No Smash and Grab

Published: Mar 28, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Retailers, e-commerce developers and security vendors should be paying close attention to the data breach case unfolding around the Hannaford Brothers Cos. Unlike many data breaches in the past that fall into the “smash and grab” category, the Hannaford breach (which may affect 4.2 million credit and debit card numbers) appears to have been a well-orchestrated theft of real-time credit data moving across the network and apparently meeting most of the current security standards.

A front page article in the Friday, March 28 Boston Globe offers previously undisclosed details of the breach. This was no case of lost back-up tapes, unprotected laptops or a tap of unprotected wireless data.

According to a letter written by Hannaford’s general counsel Emily D. Dickinson and quoted in the Globe, an “illicit and unauthorized computer program known as ‘malware’ was installed on the servers of each of the stores the company operates in Maine, Vermont, New Hampshire, Massachusetts and New York, plus at stores elsewhere…” The letter goes on to state that the data was taken “in transit for authorization from the point of sale.” The company had been recertified as meeting credit card standards as recently as February 27, 2008.

Stealing data in transit is akin to hijacking a truck as it moves down the highway. You can do it, but it takes several levels of sophistication beyond a theft of a parked vehicle. So now, the IT security detectives will start back-tracking through the Hannaford network looking at access logs, server patches and network traffic.

In two weeks, San Francisco will host the big RSA security show. There will be lots of discussion about securing data, not devices and balancing the need for security with the desire for easily accessible, fast e-commerce transactions. I expect that breaches such as the one unfolding at Hannaford will push the development of system-wide security planning that includes end-to-end encryption based on a public key infrastructure.

Eric Lundquist

Eric Lundquist

Content Writer

Since 1996, Eric Lundquist has been Editor in Chief of eWEEK, which includes domestic, international and online editions. As eWEEK's EIC, Lundquist oversees a staff of nearly 40 editors, reporters and Labs analysts covering product, services and companies in the high-technology community. He is a frequent speaker at industry gatherings and user events and sits on numerous advisory boards. Eric writes the popular weekly column, 'Up Front,' and he is a confidant of eWEEK's Spencer F. Katt gossip columnist.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。